ClickFix Removes Your Background but Leaves the Malware

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Huntress researchers dissect a ClickFix campaign dubbed 'BackgroundFix' that lures victims through a fake AI background-removal site. Clicking a fake CAPTCHA copies a malicious command to the clipboard that uses the legacy Windows finger.exe client to fetch a batch payload. The chain downloads a legitimate Python embeddable runtime, uses it as a bring-your-own-interpreter loader, and ultimately deploys CastleLoader — a custom multi-stage loader using RC4, ChaCha20, reflective PE loading, PEB rewriting, and the ReplaceTextW dialog hook trick to evade EDRs. CastleLoader then delivers NetSupport RAT for persistent remote access and CastleStealer, a .NET credential stealer targeting Chromium passwords, crypto wallet extensions, Discord tokens, and Telegram session data. Defenders can break the chain by blocking the Run dialog, blocking outbound TCP port 79 (finger), and keeping Chromium browsers updated to benefit from App-Bound Encryption.

32m read timeFrom huntress.com
Post cover image
Table of contents
BackgroundLooking into “BackgroundFix”CastleLoader technical analysisInside the castleAnother boring stealer, or should we call it CastleStealer?ConclusionDetectionsRecommendationIndicators of compromise (IOCs)
7 Impressions